Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to automatically save user-shared images to a temp path and run face identification, but it does not require any user notice or consent for biometric processing or for local storage of face-related data. Because face recognition and identity memory involve sensitive biometric information, silent processing and storage increase privacy risk and can surprise users who intended to share an image for general understanding rather than identity analysis.
